3.1 Topics of this module

Course subject(s) 3. Security Investment and Management

Topics of module #3

  • Security strategies
    • Reasons to invest in security for “security providers”
    • Reasons to invest in security for “security consumers”
  • Optimal information security investment
    • Security cost and benefits
    • Security/investment metrics
    • Gordon–Loeb model & extensions
    • Timing of security investments
  • Risk management
    • Risk acceptance vs. avoidance
    • Risk mitigation
    • Risk transfer: Cyber insurance
  • Operational security management
    • Secure software development, patch management, incident management, forensics and identity management
